Authentication (AuthN) proves who you are, while Authorization (AuthZ) verifies what permissions you possess. Modern cloud architectures have moved away from stateful server sessions and basic HTTP authentication in favor of decentralized, tokenized security.
Key Authentication & Authorization Standards
- Basic Authentication: Transmits Base64-encoded credentials on every HTTP request. Prone to credential theft if TLS terminates improperly; strictly avoided for public clients.
- OAuth 2.0 (RFC 6749): An authorization framework allowing client applications to access protected resources via scoped access tokens without handling user credentials directly.
- OpenID Connect (OIDC): An identity layer built on top of OAuth 2.0. While OAuth 2.0 issues Access Tokens for authorization, OIDC issues verifiable ID Tokens formatted as JWTs for identity verification.
- SAML 2.0: An XML-based federated identity standard widely used in enterprise Single Sign-On (SSO) systems alongside corporate directories (Okta, Ping, Azure AD).
Modern OAuth 2.0 Resource Server Configuration (Spring Boot 3 / Spring Security 6)
Legacy annotations like @EnableAuthorizationServer have been completely deprecated. Modern Spring Boot applications act as lightweight OAuth 2.0 Resource Servers validating JWT tokens issued by providers like Keycloak or Auth0:
package com.astralsurge.security;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.http.SessionCreationPolicy;
import org.springframework.security.web.SecurityFilterChain;
@Configuration
@EnableWebSecurity
public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.csrf(csrf -> csrf.disable())
.sessionManagement(session ->
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
)
.authorizeHttpRequests(auth -> auth
.requestMatchers("/public/**").permitAll()
.requestMatchers("/api/admin/**").hasAuthority("SCOPE_admin")
.anyRequest().authenticated()
)
.oauth2ResourceServer(oauth2 -> oauth2.jwt());
return http.build();
}
}
Modern Python API Authentication (FastAPI + JWT)
In modern Python stacks, flask_oauthlib is obsolete. FastAPI natively supports OAuth2 password and bearer token validation:
from fastapi import Depends, FastAPI, HTTPException, status
from fastapi.security import OAuth2PasswordBearer
import jwt
app = FastAPI()
oauth2_scheme = OAuth2PasswordBearer(tokenUrl="token")
SECRET_KEY = "enterprise-signing-secret"
ALGORITHM = "HS256"
def verify_token(token: str = Depends(oauth2_scheme)):
try:
payload = jwt.decode(token, SECRET_KEY, algorithms=[ALGORITHM])
return payload.get("sub")
except jwt.PyJWTError:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail="Could not validate credentials",
headers={"WWW-Authenticate": "Bearer"},
)
@app.get("/users/me")
def read_current_user(username: str = Depends(verify_token)):
return {"authenticated_user": username}

0 Comments